Skip to content
Visakaro

How we handle your documents

What happens to your passport after you upload it: who can open it, how long we keep it, and what we deliberately do not claim.

Applying for a visa means handing a stranger your passport. This page is the detail of what happens to it here, including the parts most services do not put in writing.

Who can open it

Uploaded documents are stored on a private disk. There is no address that serves one directly. No link you could paste to a friend, no folder a search engine can reach. Opening a document requires a signed link that stops working after 30 minutes and a check that the account asking is the one it belongs to. A leaked link on its own gets refused.

Inside Visakaro, the people who prepare and check your application can open your documents. That is the job: somebody has to confirm the photo meets the destination's specification and the passport has enough validity left.

What we remove before storing it

A photograph taken on a phone carries hidden metadata, and on most phones that includes the GPS coordinates of wherever it was taken. Since people photograph their passport at home, that file quietly records their address.

We strip it. Every image is re-encoded on upload, which removes the location, the device details and the timestamp. Only the picture is kept.

How long we keep it

  • Documents on an application are deleted once your visa has been decided, whether approved or refused. At that point the paperwork has done its job.
  • Documents in your vault, the copies kept so a second trip does not mean scanning the same passport again, are deleted after 730 days.
  • Whenever you say so. You can delete anything in your vault yourself, at any time, from your account.

Deletion is automatic and runs nightly. It is not a request you have to make.

Backups

Backups are encrypted, and they are encrypted in a way that matters: the server holds only the key needed to write them. It cannot read them back. The key that can is kept off the machine entirely, so a server compromise does not expose the history.

Payments

Card details never reach our servers. Payment happens on Razorpay's own hosted page, with Razorpay's certificate in your browser's address bar. We are told whether a payment succeeded and nothing else.

Signing in

There is no password. We send a one-time code to your phone or email, which means there is no password to forget, reuse, or have leaked from somewhere else.

What we do not claim

Some services advertise "end-to-end encryption" for documents. We do not, because for a visa service it cannot be true. End-to-end means only you hold the key and nobody at the company can open the file. That is incompatible with a human checking your passport against a consulate's requirements. Any provider claiming both is describing something they are not doing.

What we can honestly say is narrower and checkable: your documents are private, reachable only by you and the team handling your application, stripped of location data, and deleted on a schedule you can read above.

Reporting a problem

If you believe a document has been exposed or accessed improperly, tell us and we will investigate and respond.